DNN Stored Cross-Site Scripting Vulnerability in Scheduler Log Notes

Vulnerability

A stored cross-site scripting vulnerability has been identified in DNN (DotNetNuke) versions 9.0.0 prior to 9.13.10 and 10.0.0 prior to 10.2.0. This vulnerability allows extensions to write rich text in log notes, which can include scripts that execute in the PersonaBar when the notes are displayed.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the log notes.

Remediation

Users can upgrade to DNN versions 9.13.10 or 10.2.0, both of which include the necessary fix.

Added: Jan 28, 2026, 12:18 AM
Updated: Jan 28, 2026, 12:18 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
5.4
exploitability
6.4
remediation
7.7
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.